Executive brief
Oracle Hyperion Financial Management is a financial planning and consolidation application used by enterprises to manage accounting and reporting. This vulnerability allows a low-privileged network user to gain unauthorized read and write access to financial data with the help of social engineering (user interaction required). The breach could expose sensitive financial records and enable unauthorized modifications to accounting data.
Technical details
This is a privilege escalation vulnerability in the Security component of Oracle Hyperion Financial Management. The flaw requires low-level privileges, network connectivity via HTTP, and user interaction (social engineering or clickjacking). An attacker cannot exploit this without tricking a legitimate user into taking action. Once exploited, the attacker gains unauthorized read access to a subset of data and update/insert/delete access to some protected data. The vulnerability is difficult to exploit due to the required preconditions (high complexity, user interaction, low privileges). Patch availability should be confirmed via Oracle's official security advisory.
Affected products
- Oracle Hyperion Financial Management 11.2.25.0.000
Timeline
- 2026-08-18: disclosed